Recommended Microsoft Security Updates for Cisco TelePresence Content Server Release 7.x January 13, 2016 This bulletin lists the Microsoft Security Updates that are recommended for installation on the Cisco TelePresence Content Server Release 7.x. This bulletin is applicable to all versions of the Content Server with Windows 2012 R2. Contents • Installation, page 1 • Windows 2012 R2 Security Updates • Related Documentation, page 6 • Obtaining Documentation and Submitting a Service Request, page 6 Installation For each security update, click the link to go directly to the Microsoft web site and do the following: 1. Read the Microsoft Security Bulletin. 2. Download the Security Update by clicking the link on the Security Bulletin web page for Windows Server 2012 R2. 3. Install the update by following the procedure provided by Microsoft. Cisco Systems, Inc. www.cisco.com Windows 2012 R2 Security Updates Windows 2012 R2 Security Updates Microsoft Knowledge Base Article Executable File Windows Kernel Patches for Windows 2012 R2 for Content Server 7.x Vulnerability in Windows Application Compatibility Cache Could Allow Elevation of Privilege Windows8.1-KB3023266-x64.msu Vulnerability in Windows User Profile Service Windows8.1-KB3021674-x64.msu Could Allow Elevation of Privilege (KB3021674) Vulnerability in Windows Components Could Allow Elevation of Privilege (KB3025421) Windows8.1-KB3019978-x64.msu Vulnerability in Network Location Awareness Service Could Allow Security Feature Bypass (KB3022777) Windows8.1-KB3022777-x64.msu Vulnerability in Windows Error Reporting Could Windows8.1-KB3004365-v2-x64.msu Allow Security Feature Bypass (KB3004365) Vulnerability in Network Policy Server RADIUS Windows8.1-KB3014029-x64.msu Implementation Could Cause Denial of Service (KB3014029) Vulnerability in Windows Kernel-Mode Driver Windows8.1-KB3019215-x64.msu Could Allow Elevation of Privilege (KB3019215) Vulnerabilities in Windows Kernel-Mode Driver Could Allow Remote Code Execution (KB3036220) Vulnerabilities in Windows Kernel-Mode Driver Could Allow Remote Code Execution (KB3036220) Windows8.1-KB3013455-v2-x64.msu Windows8.1-KB3023562-x64.msu Vulnerability in Group Policy Could Allow Remote Code Execution (KB3000483) Windows8.1-KB3000483-x64.msu Vulnerability in Group Policy Could Allow Security Feature Bypass (KB3004361) Windows8.1-KB3004361-x64.msu Vulnerability in Microsoft Windows Could Allow Windows8.1-KB3031432-x64.msu Elevation of Privilege (KB3031432) Vulnerability in Microsoft Graphics Component Could Allow Information Disclosure (KB3029944) Windows8.1-KB3029944-x64.msu Vulnerabilities in Microsoft Windows Could Allow Remote Code Execution (KB3041836) Windows8.1-KB3033889-x64.msu Vulnerabilities in Microsoft Windows Could Allow Remote Code Execution (KB3041836) Windows8.1-KB3039066-x64.msu Vulnerabilities in Adobe Font Driver Could Allow Windows8.1-KB3032323-x64.msu Remote Code Execution (KB3032323) Vulnerabilities in Kernel-Mode Driver Could Allow Elevation of Privilege (KB3034344) Windows8.1-KB3034344-x64.msu Recommended Microsoft Security Updates for Cisco TelePresence Content Server Release 7.x 2 Windows 2012 R2 Security Updates Microsoft Knowledge Base Article Executable File Vulnerability in PNG Processing Could Allow Information Disclosure (KB3035132) Windows8.1-KB3035132-x64.msu Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (KB3038680) Windows8.1-KB3035131-x64.msu Vulnerability in NETLOGON Could Allow Spoofing (KB3002657) Windows8.1-KB3002657-x64.msu Vulnerability in Windows Task Scheduler Could Allow Security Feature Bypass (KB3030377) Windows8.1-KB3030377-x64.msu Vulnerability in Windows Photo Decoder Windows8.1-KB3035126-x64.msu Component Could Allow Information Disclosure (KB3035126) Vulnerability in Remote Desktop Protocol Could Windows8.1-KB3035017-x64.msu Allow Denial of Service (KB3039976) Vulnerability in Schannel Could Allow Security Feature Bypass (KB3046049) Windows8.1-KB3046049-x64.msu Vulnerability in HTTP.sys Could Allow Remote Code Execution (KB3042553) Windows8.1-KB3042553-x64.msu Vulnerability in Windows Task Scheduler Could Allow Elevation of Privilege (KB3046269) Windows8.1-KB3045685-x64.msu Vulnerability in Windows Task Scheduler Could Allow Elevation of Privilege (KB3046269) Vulnerabilities in Microsoft Font Drivers Could Allow Remote Code Execution (KB3057110) Vulnerabilities in Microsoft Font Drivers Could Allow Remote Code Execution (KB3057110) Vulnerability in Windows Journal Could Allow Remote Code Execution (KB3046002) Windows8.1-KB3045999-x64.msu Windows8.1-KB3048072-x64.msu Windows8.1-KB3045171-x64.msu Windows8.1-KB3046002-x64.msu Vulnerabilities in Windows Kernel-Mode Drivers Windows8.1-KB3045171-x64.msu Could Allow Elevation of Privilege (KB3057191) Vulnerability in Windows Kernel Could Allow Security Feature Bypass (KB3050514) Windows8.1-KB3050514-x64.msu Vulnerability in Microsoft Management Console File Format Could Allow Denial of Service (KB3051768) Windows8.1-KB3051768-x64.msu Vulnerability in Schannel Could Allow Information Disclosure (KB3061518) Windows8.1-KB3061518-x64.msu Vulnerability in Microsoft Common Controls Could Allow Remote Code Execution (KB3059317) Windows8.1-KB3059317-x64.msu Vulnerabilities in Windows Kernel-Mode Drivers Windows8.1-KB3057839-x64.msu Could Allow Elevation of Privilege (KB3057839) Vulnerabilities in Windows Hyper-V Could Allow Windows8.1-KB3046359-x64.msu Remote Code Execution (KB3072000) Recommended Microsoft Security Updates for Cisco TelePresence Content Server Release 7.x 3 Windows 2012 R2 Security Updates Microsoft Knowledge Base Article Executable File Vulnerabilities in Windows Could Allow Remote Windows8.1-KB3061512-x64.msu Code Execution (KB3072631) Vulnerability in Netlogon Could Allow Elevation Windows8.1-KB3068457-x64.msu of Privilege (KB3068457) Vulnerability in Windows Graphics Component Windows8.1-KB3069392-x64.msu Could Allow Elevation of Privilege (KB3069392) Vulnerabilities in Windows Kernel-Mode Driver Windows8.1-KB3070102-x64.msu Could Allow Elevation of Privilege (KB3070102) Vulnerability in Windows Installer Service Could Windows8.1-KB3072630-x64.msu Allow Elevation of Privilege (KB3072630) Vulnerabilities in OLE Could Allow Elevation of Windows8.1-KB3072633-x64.msu Privilege (KB3072633) Vulnerability in Windows Remote Procedure Call Windows8.1-KB3067505-x64.msu Could Allow Elevation of Privilege (KB3067505) Vulnerabilities in Microsoft Graphics Component Windows8.1-KB3078601-x64.msu Could Allow Remote Code Execution (KB3078662) Vulnerabilities in RDP Could Allow Remote Code Execution (KB3080348) Windows8.1-KB3075220-x64.msu Vulnerability in Mount Manager Could Allow Elevation of Privilege (KB3082487) Windows8.1-KB3071756-x64.msu Unsafe Command Line Parameter Passing Could Windows8.1-KB3046017-x64.msu Allow Information Disclosure (KB3082458) Vulnerability in WebDAV Could Allow Information Disclosure (KB3076949) Windows8.1-KB3076949-x64.msu Vulnerabilities in Microsoft Windows Could Allow Elevation of Privilege (KB3060716) Windows8.1-KB3060716-x64.msu Vulnerability in Active Directory Service Could Allow Denial of Service (KB3072595) Windows8.1-KB3072595-x64.msu Vulnerabilities in Microsoft Graphics Component Windows8.1-KB3087039-x64.msu Could Allow Remote Code Execution (KB3089656) Vulnerabilities in Windows Journal Could Allow Remote Code Execution (KB3089669) Windows8.1-KB3069114-x64.msu Windows8.1-KB3082089-x64.msu Vulnerabilities in Windows Task Management Could Allow Elevation of Privilege (KB3089657) Vulnerabilities in Windows Task Management Windows8.1-KB3084135-x64.msu Could Allow Elevation of Privilege (KB3089657) Vulnerability in Windows Hyper-V Could Allow Security Feature Bypass (KB3091287) Windows8.1-KB3087088-x64.msu Security Update for Windows Shell to Address Remote Code Execution (KB3096443) Windows8.1-KB3080446-x64.msu Recommended Microsoft Security Updates for Cisco TelePresence Content Server Release 7.x 4 Windows 2012 R2 Security Updates Microsoft Knowledge Base Article Executable File Security Update for Windows Kernel to Address Elevation of Privilege (KB3096447) Windows8.1-KB3088195-x64.msu Security Update for Microsoft Windows to Address Remote Code Execution (KB3105864) Windows8.1-KB3097877-x64.msu Follow installation sequence: Security Update for Kerberos to Address Security Windows8.1-KB3101246-x64.msu Feature Bypass (KB3105256) Security Update for Microsoft Windows to Address Remote Code Execution (KB3105864) Windows8.1-KB3101746-x64.msu Security Update for Schannel to Address Spoofing (KB3081320) Windows8.1-KB3081320-x64.msu Security Update for Winsock to Address Elevation of Privilege (KB3104521) Windows8.1-KB3092601-x64.msu Security Update for IPSec to Address Denial of Service (KB3102939) Windows8.1-KB3102939-x64.msu Security Update for Microsoft Graphics Component to Address Remote Code Execution (KB3104503) Windows8.1-KB3109094-x64.msu Security Update for Microsoft Windows to Address Remote Code Execution (KB3116162) Windows8.1-KB3108347-x64.msu Security Update for Microsoft Windows to Address Remote Code Execution (KB3116162) Windows8.1-KB3108381-x64.msu Security Update for Windows PGM to Address Elevation of Privilege (KB3116130) Windows8.1-KB3109103-x64.msu Security Update for Windows Kernel-Mode Drivers to Address Elevation of Privilege (KB3119075) Windows8.1-KB3109094-x64.msu Category 2: Windows Patches for Application Server Vulnerabilities in XML Core Services Could Allow Information Disclosure (KB3080129) Windows8.1-KB3076895-x64.msu Category 3: Windows Patches for Application and Frameworks Vulnerability in .NET Framework Could Allow Information Disclosure (KB3048010) Windows8.1-KB3037576-x64.msu Vulnerability in .NET Framework Could Allow Information Disclosure (KB3048010) Windows8.1-KB3037579-arm.msu Windows8.1-KB3037579-x64.msu Vulnerabilities in .NET Framework Could Allow Windows8.1-KB3023219-x64.msu Elevation of Privilege (KB3057134) Vulnerabilities in .NET Framework Could Allow Windows8.1-KB3035487-x64.msu Elevation of Privilege (KB3057134) Vulnerabilities in .NET Framework Could Allow Windows8.1-KB3023222-x64.msu Elevation of Privilege (KB3057134) Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (KB3057134) Windows8.1-KB3032663-x64.msu Recommended Microsoft Security Updates for Cisco TelePresence Content Server Release 7.x 5 Related Documentation Microsoft Knowledge Base Article Executable File Vulnerabilities in .NET Framework Could Allow Windows8.1-KB3083185-x64.msu Elevation of Privilege (kb3086251) Vulnerabilities in .NET Framework Could Allow Windows8.1-KB3074545-x64.msu Elevation of Privilege (KB3089662) Vulnerabilities in .NET Framework Could Allow Windows8.1-KB3074548-x64.msu Elevation of Privilege (KB3089662) Vulnerabilities in .NET Framework Could Allow Windows8.1-KB3074553-x64.msu Elevation of Privilege (KB3089662) Security Update for .NET Framework to Address Windows8.1-KB3097992-x64.msu Elevation of Privilege (KB3104507) Security Update for .NET Framework to Address Windows8.1-KB3097997-x64.msu Elevation of Privilege (KB3104507) Security Update for .NET Framework to Address Windows8.1-KB3098000-x64.msu Elevation of Privilege (KB3104507) Related Documentation Cisco TelePresence Content Server Documentation http://www.cisco.com/en/US/products/ps11347/tsd_products_support_series_home.html Information About Accessibility and Cisco Products For information about the accessibility of this product, contact the Cisco accessibility team at accessibility@cisco.com. Obtaining Documentation and Submitting a Service Request For information on obtaining documentation, using the Cisco Bug Search Tool (BST), submitting a service request, and gathering additional information, see What’s New in Cisco Product Documentation at: http://www.cisco.com/en/US/docs/general/whatsnew/whatsnew.html. Subscribe to What’s New in Cisco Product Documentation, which lists all new and revised Cisco technical documentation, as an RSS feed and deliver content directly to your desktop using a reader application. The RSS feeds are a free service. This document is to be used in conjunction with the documents listed in the “Related Documentation” section. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R) Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental. © 2014 Cisco Systems, Inc. All rights reserved. Recommended Microsoft Security Updates for Cisco TelePresence Content Server Release 7.x 6